Google Takes Down Malicious Chrome Extensions that Steal Cryptocurrency Wallet Credentials

Google Takes Down Malicious Chrome Extensions that Steal Cryptocurrency Wallet Credentials
фото показано с : beincrypto.com

2020-4-17 00:10

Google has done a little spring cleaning in its Chrome Web Store leading to the removal of a swath of malicious cryptocurrency-stealing app extensions in a single sweep.

The internet giant has shut down 49 malicious Chrome extensions from the app marketplace. The extensions were found to have been stealing cryptocurrency keys and wallet details from users.

Google Targets Bogus Crypto Wallet Apps

The malicious extensions were discovered by Harry Denley, the Director of Security at the MyCrypto platform. Denley told ZDNet that most of these extensions are camouflaged as legitimate wallet apps. However, they contain malicious code that enables them to steal private keys, mnemonic phrases, and other relevant information.

Denley clarified that some of the prominent wallet apps that these clones mimic include Trevor, KeepKey, Ledger, Exodus, and MyEtherWallet. These fake extensions all work identical to the original apps, but any details that customers enter on the fake extensions are immediately sent to the attackers’ server.

He also added that the extensions appear to have been developed by a cybercrime group which he suspects to be from Russia.

The security executive also pointed out that most of the thefts don’t happen immediately. Per an experiment he carried out, he realized that the hackers don’t actually steal funds as soon as they get the login credentials. He argues that it’s either the attackers haven’t gotten a grasp of how to automate their processes (and as such, is manually accessing each account), or they’re more interested in stealing from high-value targets alone.

Significant Threat to the Safety of the Industry

The threat of fake browser extensions in the crypto space has always been a prominent one. Last month, Ledger warned its users about a fake Chrome extension wreaking havoc and stealing funds.

According to the French cryptocurrency wallet manufacturer, the malicious browser extension was requesting users’ recovery seeds, which would then be used to access their accounts.

The fake extension in question tried to mimic Ledger Live, an extension that allows users to sync their Ledger wallets with a trusted device and approve transactions in Chrome.

The post Google Takes Down Malicious Chrome Extensions that Steal Cryptocurrency Wallet Credentials appeared first on BeInCrypto.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Single Collateral DAI (SAI) на Currencies.ru

$ 1.2856 (-0.12%)
Объем 24H $902
Изменеия 24h: 5.18 %, 7d: 20.67 %
Cегодня L: $1.2856 - H: $1.2856
Капитализация $8.563m Rank 99999
Цена в час новости $ 0.997 (28.95%)

extensions chrome malicious google app down cryptocurrency-stealing

extensions chrome → Результатов: 27


Фото:

Google will remove shady data-stealing Chrome extensions starting October 15

Google is making good on its “root-and-branch review” of third-party developer access to user data. The company has now said its new policy for Minimum Permission and updated User Data policy will be enforced starting October 15, 2019 — in other words, Chrome will no longer support sketchy extensions that gather data on your browsing activity.

2019-7-24 08:46


Фото:

Google is cracking down on Drive and Chrome extensions that abuse your data

Google is expanding its privacy audit to make third-party developer access to Chrome and Google Drive more secure. To that effect, developers must rework their Chrome extensions to request only minimum permissions without compromising their functionality “We’re requiring extensions to only request access to the appropriate data needed to implement their features,” Google outlined on its Safety and Security page.

2019-5-31 11:41